CVE-2026-53639 is an insecure direct object reference vulnerability in Sylius Shop Payment Request API endpoints. The flaw allows access control to be bypassed when payment requests or related orders are referenced using identifiers such as a payment request hash or an order token value without sufficient ownership validation. An attacker who knows or obtains a valid payment request hash can retrieve payment request information and derive the associated order token, which can then be used to access full order details. The affected functionality also permits unauthorized modification of redirect-related payment request fields, including values used to control post-payment navigation. In addition, the payment-request creation endpoint for shop orders allows unauthorized access to orders based solely on token-based reference data rather than verified authorization context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.